CVE-2022-0817

CVE-2022-0817: BadgeOS <= 3.7.0 - Unauthenticated SQLi

Vendor Unknown
Product BadgeOS
Weakness CWE-89 · SQLi
Published May 9, 2022
Last update August 2, 2024

CVSS base score

What the vulnerability does

01Description

The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

Key dates

02Disclosure timeline

May 9, 2022 CVE published
August 2, 2024 Record updated